CVE-2020-35359
HIGHNuclei
Pure-FTPd 1.0.48 - Remote Denial of Service
Record summary
CVE-2020-35359 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBPure-FTPd 1.0.48 - Remote Denial of ServiceExploitDB exploitby xynmapsNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHPure-FTPd 1.0.48 - Denial of ServiceCVSS 7.5
Pure-FTPd 1.0.48 is vulnerable to Denial of Service via exhaustion of connections due to lack of proper connection limits.
Impact
Unauthenticated attackers can exhaust available connections due to lack of proper connection limits, causing denial of service by preventing legitimate users from connecting to the FTP server.
Remediation
Update Pure-FTPd to a version newer than 1.0.48 that implements proper connection limits and rate limiting to prevent connection exhaustion attacks.
WeaknessesCWE-770
Authorspussycat0x
Template tagscvecve2020networkftppure-ftpdtcppassivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:a:pureftpd:pure-ftpd:1.0.48:*:*:*:*:*:*:*
Shodan: product:"pure-ftpd"
Shodan: cpe:"cpe:2.3:a:pureftpd:pure-ftpd"
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35359 exploit-db.com
https://www.exploit-db.com/exploits/49105